A coordinated operation involving 131 Chrome extensions has been uncovered, with all extensions abusing WhatsApp Web to automate spam messaging at scale. These extensions, which are essentially rebrands of a single tool, share the same codebase, design patterns, and backend infrastructure, indicating a deliberate attempt to evade detection and maximize reach. The extensions inject code directly into the WhatsApp Web interface, running alongside legitimate scripts to automate bulk outreach and message scheduling. This activity is designed to bypass WhatsApp’s anti-spam mechanisms, enabling the operators to send unsolicited messages to large numbers of users. Marketing materials for these extensions falsely claim that their presence in the Chrome Web Store implies a rigorous security audit and full privacy compliance, misleading potential users and resellers. Contrary to these claims, the extensions violate both Chrome Web Store and WhatsApp policies by facilitating spam and unauthorized automation. At least 20,905 active users have been identified across the various extension listings, with some individual extensions, such as YouSeller, amassing over 10,000 users. The operation has been ongoing for at least nine months, with regular waves of new uploads and version updates observed throughout 2025, including as recently as mid-October. The extensions are marketed under different names, logos, and landing pages, but all provide the same WhatsApp Web automation interface, confirming their common origin. Security researchers have filed takedown requests with the Chrome security team and have called for the suspension of the associated publisher accounts. The Socket AI Scanner has flagged at least one extension, Organize-C, as malware due to its spamware behavior. The widespread availability of these extensions on the Chrome Web Store highlights significant gaps in extension vetting and enforcement. The operation’s scale and persistence suggest a lucrative reseller scheme, with the extensions being promoted as tools for mass outreach and marketing. The abuse of Chrome’s extension ecosystem for such purposes poses risks not only to WhatsApp users but also to the broader web platform. The incident underscores the need for improved monitoring and enforcement of extension policies by browser vendors. WhatsApp and Chrome users are advised to be vigilant about installing third-party extensions, especially those that promise automation or mass messaging capabilities. The exposure of this scheme may prompt further investigations into similar abuse patterns across other web platforms.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
Following the initial disclosure, several security news outlets reported on the same campaign, highlighting that more than 100 Chrome extensions were hijacking or automating WhatsApp Web for mass messaging and spam. These reports did not introduce a separate incident but amplified the scale and abuse pattern already identified.
Security researchers uncovered a large cluster of 131 Chrome extensions designed to automate or facilitate spam activity through WhatsApp Web, including bypassing platform anti-spam controls. The extensions were described as part of a broad reseller-driven spamware scheme distributed through the Chrome Web Store.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
4 references tracked. Mallory keeps watching after this page renders.
malwarebytes.com
Open sourcesecurityonline.info
Open sourcethehackernews.com
Open sourcesocket.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.